CVE-2014-4466: High severity iphone os vulnerability
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4466?
CVE-2014-4466 has a medium severity rating, as it allows remote attackers to execute arbitrary code or cause application crashes.
How do I fix CVE-2014-4466?
To mitigate CVE-2014-4466, users should update their Apple Safari browser to version 8.0.1 or later, or upgrade their affected Apple devices to the latest operating system.
What types of devices are affected by CVE-2014-4466?
CVE-2014-4466 affects Apple Safari versions prior to 8.0.1, as well as iPhone OS versions up to 8.1.2 and tvOS versions up to 7.0.1.
Can CVE-2014-4466 be exploited remotely?
Yes, CVE-2014-4466 can be exploited remotely through a crafted website, leading to potential denial of service and memory corruption.
Is CVE-2014-4466 a known vulnerability?
Yes, CVE-2014-4466 is a recognized vulnerability documented in security advisories released by Apple.